Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2016:1584-1 Important: NTP Security Issues Resolution

suse
Calendar Grey June 15, 2016
Dist Suse Esm H88
Crucial SUSE patch resolves vulnerabilities in ntp, including comprehensive solutions and guidelines for implementation.
An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes ...

Summary

ntp was updated to version 4.2.8p8 to fix five security issues. These security issues were fixed: - CVE-2016-4953: Bad authentication demobilizes ephemeral associations (bsc#982065). - CVE-2016-4954: Processing spoofed server packets (bsc#982066). - CVE-2016-4955: Autokey association reset (bsc#982067). - CVE-2016-4956: Broadcast interleave (bsc#982068). - CVE-2016-4957: CRYPTO_NAK crash (bsc#982064). These non-security issues were fixed: - Keep the parent process alive until the daemon has finished initialisation, to make sure that the PID file exists when the parent returns. - bsc#979302: Change the process name of the forking DNS worker process to avoid the impression that ntpd is started twice. - bsc#981422: Don't ignore SIGCHILD because it breaks wait().

References

#979302 #981422 #982056 #982064 #982065 #982066

#982067 #982068

Cross- CVE-2016-4953 CVE-2016-4954 CVE-2016-4955

CVE-2016-4956 CVE-2016-4957

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2016-4953.html

https://www.suse.com/security/cve/CVE-2016-4954.html

https://www.suse.com/security/cve/CVE-2016-4955.html

https://www.suse.com/security/cve/CVE-2016-4956.html

https://www.suse.com/security/cve/CVE-2016-4957.html

https://bugzilla.suse.com/979302

https://bugzilla.suse.com/981422

https://bugzilla.suse.com/982056

https://bugzilla.suse.com/982064

https://bugzilla.suse.com/982065

https://bugzilla.suse.com/982066

https://bugzilla.suse.com/982067

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1584-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here